91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 3,451–3,500 of 8,161 in High · page 70 of 164

IDTitleSummary
CVE-2025-7755CVE-2025-7755
CVSS 8.8
A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /a…
CVE-2025-7747CVE-2025-7747
CVSS 8.8
A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromWizardHandle of the file /goform/WizardHandle of th…
CVE-2025-7722CVE-2025-7722
CVSS 8.8
The Social Streams plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.1. This is due to the plugin not proper…
CVE-2025-7718CVE-2025-7718
CVSS 8.8
The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up…
CVE-2025-7695CVE-2025-7695
CVSS 8.8
The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within its reset_password_link REST en…
CVE-2025-7692CVE-2025-7692
CVSS 8.1
The Orion Login with SMS plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.5. This is due to the olws_handl…
CVE-2025-7691CVE-2025-7691
CVSS 8.8
A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 …
CVE-2025-7689CVE-2025-7689
CVSS 8.8
The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tfhb_reset_password_callback() function i…
CVE-2025-7679CVE-2025-7679
CVSS 8.1
The ASPECT system allows users to bypass authentication. This issue affects all versions of ASPECT
CVE-2025-7667CVE-2025-7667
CVSS 8.1
The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing o…
CVE-2025-7665CVE-2025-7665
CVSS 8.1
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'handle_mofir…
CVE-2025-7657CVE-2025-7657
CVSS 8.8
Use after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch…
CVE-2025-7656CVE-2025-7656
CVSS 8.8
Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chro…
CVE-2025-7654CVE-2025-7654
CVSS 8.8
Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes it possible for authenticated attackers…
CVE-2025-7645CVE-2025-7645
CVSS 8.1
The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to arbitrary file deletion due to insuf…
CVE-2025-7640CVE-2025-7640
CVSS 8.1
The hiWeb Export Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.0.0. This is due to missing o…
CVE-2025-7636CVE-2025-7636
CVSS 8.8
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ergosis Security Systems Computer Industry and Trade Inc.…
CVE-2025-7631CVE-2025-7631
CVSS 8.6
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tumeva Internet Technologies Software Information Adverti…
CVE-2025-7628CVE-2025-7628
CVSS 8.1
A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. It has been classified as critical. This affects t…
CVE-2025-7620CVE-2025-7620
CVSS 8.8
The cross-browser document creation component produced by Digitware System Integration Corporation has a Remote Code Execution vulnerability. If a user visits …
CVE-2025-7619CVE-2025-7619
CVSS 8.8
BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability. If a user visits a malicious website while th…
CVE-2025-7615CVE-2025-7615
CVSS 8.8
A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748. Affected by this vulnerability is the function clearPairCfg of the file /cgi-bin/c…
CVE-2025-7614CVE-2025-7614
CVSS 8.8
A vulnerability classified as critical has been found in TOTOLINK T6 4.1.5cu.748. Affected is the function delDevice of the file /cgi-bin/cstecgi.cgi of the co…
CVE-2025-7613CVE-2025-7613
CVSS 8.8
A vulnerability was found in TOTOLINK T6 4.1.5cu.748. It has been rated as critical. This issue affects the function CloudSrvVersionCheck of the file /cgi-bin/…
CVE-2025-7600CVE-2025-7600
CVSS 8.8
A vulnerability, which was classified as critical, was found in PHPGurukul Online Library Management System 3.0. This affects an unknown part of the file /admi…
CVE-2025-7599CVE-2025-7599
CVSS 8.8
A vulnerability, which was classified as critical, has been found in PHPGurukul Dairy Farm Shop Management System 1.3. Affected by this issue is some unknown f…
CVE-2025-7598CVE-2025-7598
CVSS 8.8
A vulnerability classified as critical was found in Tenda AX1803 1.0.0.1. Affected by this vulnerability is the function formSetWifiMacFilterCfg of the file /g…
CVE-2025-7597CVE-2025-7597
CVSS 8.8
A vulnerability classified as critical has been found in Tenda AX1803 1.0.0.1. Affected is the function formSetMacFilterCfg of the file /goform/setMacFilterCfg…
CVE-2025-7596CVE-2025-7596
CVSS 8.8
A vulnerability was found in Tenda FH1205 2.0.0.7(775). It has been rated as critical. This issue affects the function formWifiExtraSet of the file /goform/Wif…
CVE-2025-7592CVE-2025-7592
CVSS 8.8
A vulnerability has been found in PHPGurukul Dairy Farm Shop Management System 1.3 and classified as critical. Affected by this vulnerability is an unknown fun…
CVE-2025-7591CVE-2025-7591
CVSS 8.8
A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System 1.3. Affected is an unknown function of the file v…
CVE-2025-7590CVE-2025-7590
CVSS 8.8
A vulnerability, which was classified as critical, has been found in PHPGurukul Dairy Farm Shop Management System 1.3. This issue affects some unknown processi…
CVE-2025-7589CVE-2025-7589
CVSS 8.8
A vulnerability classified as critical was found in PHPGurukul Dairy Farm Shop Management System 1.3. This vulnerability affects unknown code of the file edit-…
CVE-2025-7588CVE-2025-7588
CVSS 8.8
A vulnerability classified as critical has been found in PHPGurukul Dairy Farm Shop Management System 1.3. This affects an unknown part of the file edit-produc…
CVE-2025-7586CVE-2025-7586
CVSS 8.8
A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. Affected by this vulnerability is the function formSetAPCfg of the fi…
CVE-2025-7585CVE-2025-7585
CVSS 8.8
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been classified as critical. Affected is an unknown function of the file /admi…
CVE-2025-7584CVE-2025-7584
CVSS 8.8
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2 and classified as critical. This issue affects some unknown processing of the file /ad…
CVE-2025-7583CVE-2025-7583
CVSS 8.8
A vulnerability has been found in PHPGurukul Online Fire Reporting System 1.2 and classified as critical. This vulnerability affects unknown code of the file /…
CVE-2025-7582CVE-2025-7582
CVSS 8.8
A vulnerability, which was classified as critical, was found in PHPGurukul Online Fire Reporting System 1.2. This affects an unknown part of the file /admin/as…
CVE-2025-7581CVE-2025-7581
CVSS 8.8
A vulnerability, which was classified as critical, has been found in code-projects Voting System 1.0. Affected by this issue is some unknown functionality of t…
CVE-2025-7580CVE-2025-7580
CVSS 8.8
A vulnerability classified as critical was found in code-projects Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /ad…
CVE-2025-7571CVE-2025-7571
CVSS 8.8
A vulnerability classified as critical has been found in UTT HiPER 840G up to 3.1.1-190328. This affects an unknown part of the file /goform/aspApBasicConfigUr…
CVE-2025-7570CVE-2025-7570
CVSS 8.8
A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been rated as critical. Affected by this issue is some unknown functionality of the file…
CVE-2025-7568CVE-2025-7568
CVSS 8.8
A vulnerability was found in qianfox FoxCMS up to 1.2.5. It has been classified as critical. Affected is the function batchCope of the file app/admin/controlle…
CVE-2025-7563CVE-2025-7563
CVSS 8.8
A vulnerability classified as critical was found in PHPGurukul Online Fire Reporting System 1.2. Affected by this vulnerability is an unknown functionality of …
CVE-2025-7562CVE-2025-7562
CVSS 8.8
A vulnerability classified as critical has been found in PHPGurukul Online Fire Reporting System 1.2. Affected is an unknown function of the file /admin/new-re…
CVE-2025-7561CVE-2025-7561
CVSS 8.8
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been rated as critical. This issue affects some unknown processing of the file…
CVE-2025-7560CVE-2025-7560
CVSS 8.8
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been declared as critical. This vulnerability affects unknown code of the file…
CVE-2025-7559CVE-2025-7559
CVSS 8.8
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been classified as critical. This affects an unknown part of the file /admin/b…
CVE-2025-7558CVE-2025-7558
CVSS 8.8
A vulnerability was found in code-projects Voting System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admi…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.